aaronpk / oauth-first-party-apps

https://datatracker.ietf.org/doc/html/draft-parecki-oauth-first-party-apps
Other
10 stars 8 forks source link

REQUIRED in annex B is confusing #108

Open Sakurann opened 1 month ago

Sakurann commented 1 month ago

If it is required, it is not an example, and should probably be in the main text.

"username": REQUIRED for the initial Authorization Challenge Request.

"otp": The OTP collected from the user. REQUIRED when re-trying an Authorization Challenge Request in response to the otp_required error defined below.